Vulnerability Response Senior SME – Cybersecurity & Risk Management
25 410 - 30 660
PLN
(B2B)
18 200 - 22 000
PLN
brutto (Employment Contract)
Empower proactive defense — lead the charge in vulnerability response and security resilience!
Kraków-based opportunity with hybrid work model (4 days remote, 1 day office).
As a Vulnerability Response Senior SME, you will be working for our client within the Cybersecurity team, dedicated to safeguarding global financial services through advanced vulnerability management, threat assessment, and security testing. You’ll be instrumental in shaping the organization’s security posture by evaluating threats, coordinating remediation efforts, and ensuring compliance with regulatory standards. This role offers an exciting career trajectory in cybersecurity risk management and threat mitigation.
Your main responsibilities:
- Review critical and high-severity vulnerabilities from sources such as NIST/NVD and vendor advisories, providing clear impact summaries to stakeholders.
- Validate vulnerabilities by gathering technical evidence and confirm whether they pose true threats to the organization’s estate.
- Map vulnerabilities to assets and work with service owners to identify impacted components accurately.
- Recommend practical remediation measures, including patches, configurations, and compensating controls, to mitigate risks effectively.
- Produce comprehensive technical reports detailing root causes, attack pathways, and step-by-step mitigation strategies.
- Coordinate remediation efforts with infrastructure, platform, and application teams, tracking progress and outcomes.
- Verify the effectiveness of remediation actions through re-scanning and validation testing.
- Support regulatory, audit, and governance requests by providing precise documentation and analysis.
- Assist operational teams with escalations and ad hoc cybersecurity activities as needed.
You're ideal for this role if you have:
- At least 5 years of experience in IT Security or related fields.
- Proven expertise in reviewing and assessing high-severity vulnerabilities from NIST/NVD and vendor sources.
- Strong understanding of common vulnerability types and attack techniques, such as remote code execution, privilege escalation, or authentication bypass.
- Hands-on knowledge of vulnerability identification tools like Tenable, SAST, and DAST testing methodologies.
- Solid understanding of the CI/CD pipeline, including security testing and remediation integration.
- Experience working in both on-premises and cloud environments.
- Technical skills across networking, application delivery, and security controls such as WAFs, load balancers, and TLS certificates.
- Excellent stakeholder management skills coupled with strong written communication abilities in English.
It is a strong plus if you have:
- Certifications in cybersecurity or vulnerability management (e.g., CISSP, OSCP)
- Experience with regulatory or audit engagements in cybersecurity compliance.
Language Required for the role:
- Fluent English
Eligibility for the role:
- Only candidates with an existing legal right to work in the European Union will be considered for this role.
#MAKEYourCareerBETTER
Interested? Apply now and include your CV (preferably in English) along with a statement confirming your consent to the processing and storage of your personal data.
Internal number #9801
Dodatki
ITDS Clubs
Access to medical insurance
Access to Multisport
Access to Pluralsight
Integrational Events
Ambassador Program
Twoje kryteria